|
216991
|
4.8 |
MEDIUM
Network
|
ory
|
fosite
|
ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite from version 0.30.2 and before version 0.34.1, there is an issue in which an an attacker can override the registered…
|
CWE-601
Open Redirect
|
CVE-2020-15233
|
2024-11-21 14:05 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216992
|
8.1 |
HIGH
Network
|
zohocorp
|
manageengine_desktop_central manageengine_remote_access_plus
|
A design issue was discovered in GetInternetRequestHandle, InternetSendRequestEx and InternetSendRequestByBitrate in the client side of Zoho ManageEngine Desktop Central 10.0.552.W and Remote Access …
|
NVD-CWE-Other
|
CVE-2020-15589
|
2024-11-21 14:05 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216993
|
9.1 |
CRITICAL
Network
|
mapfish
|
print
|
In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style.
|
-
|
CVE-2020-15232
|
2024-11-21 14:05 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216994
|
6.1 |
MEDIUM
Network
|
mapfish
|
print
|
In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting.
|
-
|
CVE-2020-15231
|
2024-11-21 14:05 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216995
|
6.5 |
MEDIUM
Network
|
vapor_project
|
vapor
|
Vapor is a web framework for Swift. In Vapor before version 4.29.4, Attackers can access data at arbitrary filesystem paths on the same host as an application. Only applications using FileMiddleware …
|
-
|
CVE-2020-15230
|
2024-11-21 14:05 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216996
|
8.8 |
HIGH
Network
|
mozilla opensuse debian
|
firefox_esr thunderbird firefox leap debian_linux
|
When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs because the function APZCTreeManager::ComputeClipped…
|
CWE-416
Use After Free
|
CVE-2020-15678
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216997
|
6.1 |
MEDIUM
Network
|
mozilla debian opensuse
|
firefox_esr thunderbird firefox debian_linux leap
|
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open red…
|
CWE-601
Open Redirect
|
CVE-2020-15677
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216998
|
6.1 |
MEDIUM
Network
|
mozilla debian opensuse
|
firefox_esr thunderbird firefox debian_linux leap
|
Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditabl…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15676
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216999
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 81.
|
CWE-416
Use After Free
|
CVE-2020-15675
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217000
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl…
|
CWE-787 CWE-667
Out-of-bounds Write Improper Locking
|
CVE-2020-15674
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|